Back to skill

Security audit

Openapi Docs Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-helper skill with sloppy broad triggers, but the artifacts do not show hidden execution, credential access, persistence, or destructive behavior.

Before installing, be aware that the skill may activate for some generic API or developer-experience prompts because its triggers are broad. It appears safe as a documentation aid, but a publisher should tighten trigger wording to OpenAPI/Swagger documentation tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are generic and template-like, so they can match a wide range of ordinary user requests and cause the skill to activate when the user did not explicitly intend to invoke it. In a documentation-focused skill this is not directly code-execution dangerous, but unintended invocation can override better-suited workflows, expose users to irrelevant guidance, and increase the chance of prompt-routing abuse or confusion.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger phrases are broad, templated, and partially malformed, which can cause the skill to activate for loosely related requests rather than clear user intent. In an agent environment, overbroad activation can route unrelated prompts into this skill, increasing the chance of inappropriate guidance, prompt-scope confusion, or accidental handling of sensitive API/documentation tasks without explicit user request.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description is very broad and includes generic terms like "software-and-data" and common API-related topics, which can cause the skill to activate outside narrowly intended OpenAPI/Swagger use cases. Over-broad invocation increases the chance that unrelated user requests are routed into this skill, leading to inappropriate handling, confusion, or interference with more suitable skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases are vague, malformed, and similar to ordinary conversational requests, making accidental or overly frequent invocation more likely. Because the skill is positioned as generally helping with practical workflows, ambiguous examples can expand matching behavior beyond the intended documentation scope and degrade routing safety.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill description uses broad trigger conditions such as software-and-data, openapi, swagger, api documentation, and rest api without clear exclusion boundaries. This can cause the skill to activate for loosely related requests, increasing the chance of misrouting user tasks and unintentionally applying this skill's workflow in contexts where it is not appropriate.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The keyword list contains generic terms that overlap with many normal engineering conversations, especially openapi, swagger, api documentation, and developer experience. Overly broad keywords can lead to accidental invocation, which may expose downstream systems to prompt-routing mistakes or cause irrelevant instructions to override more suitable skills.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger phrases are generic and malformed, and they do not provide contrasting non-trigger examples. Without clear examples of what should not activate the skill, implementers may interpret the routing rule too broadly, leading to frequent false activations and reduced trust in skill isolation.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation (`allow_implicit_invocation: true`) without any visible narrowly scoped activation criteria or guardrails. That increases the chance the agent will invoke this skill in unintended contexts, potentially exposing user data or allowing the skill's instructions to influence workflows when the user did not explicitly request OpenAPI documentation help.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so broad and malformed that it could match routine user language unrelated to an intentional skill invocation. This increases the chance of accidental activation, causing the agent to inject domain-specific behavior or assumptions into conversations where the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation phrase is ambiguous because it combines a generic request pattern ('I need a practical workflow for') with requirement text rather than a precise activation condition. An attacker or ordinary user could unintentionally or strategically cause skill routing by echoing this wording, leading to misclassification and inappropriate execution context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.